← All posts / Policy

163 Crimes, 20 Forces, One Curve: UK Police Put a Number on the Deepfake Epidemic

Twenty police forces in England and Wales recorded 163 crimes tagged 'AI-generated', 'deepfake' or 'nudify' by July 2026 — up from just 10 in 2023 — landing days after ministers moved to force device-level blocking on Apple and Google.

163 Crimes, 20 Forces, One Curve: UK Police Put a Number on the Deepfake Epidemic

For most of the past three years, the debate over AI-generated sexual imagery in the UK has run on survey data, charity estimates, and horror stories from individual court cases. On September 12, 2026, it finally got a number from the institutions that count crime for a living. Reporting by Mark Tovey in The Telegraph found that twenty police forces across England and Wales had recorded 163 crimes returned by searches for terms including “AI-generated”, “deepfake” and “nudify” by July 2026. In 2023, the same keywords produced ten recorded offences. That is roughly a sixteen-fold rise in three years — and it arrives at the exact moment the British government has decided to stop asking platforms for cooperation and start legislating.

What the data actually says

The figures come from police recorded-crime systems, where forces tag cases with keywords rather than distinct statutory offences. The searches captured crimes involving AI-generated nude images of children on the rise, and — per the report’s subtitle — forces seeing a surge in deepfake technology being used to “undress women,” often starting from ordinary photos taken from social media profiles.

Two caveats matter before reading too much into the curve. First, this is a floor, not a ceiling: it covers twenty forces, and keyword tagging is inconsistent across the country’s police systems. Second, as AI Weekly’s editors noted in their summary of the report, a sixteen-fold keyword-tagged rise does not by itself settle how much is a genuine surge in offending versus forces simply catching up with the language — learning that a case involving a “nudify” app should be recorded as such. Both things can be true at once. The independent evidence from the Internet Watch Foundation (IWF) suggests a real surge is a large part of the story.

The context that makes 163 alarming

The police numbers do not exist in a vacuum. They land on top of a stack of increasingly grim statistics from the UK’s online-safety apparatus:

  • The IWF detected 3,440 AI-generated videos of child sexual abuse in 2025 — up from just 13 the year before, a roughly 260-fold increase — contributing to what the foundation called the worst year for online abuse in its 30-year history. Around 7,063 AI-generated images and videos were realistic enough to be actioned as “real” imagery.
  • In her September 8 statement to the Commons, Culture Secretary Lisa Nandy said the IWF believes 91% of the intimate images involved are self-generated by children themselves, subsequently used for blackmail and sexual extortion. Around 9,000 child sexual abuse offences each year involve an online element, and under-18s are the subject of almost a quarter of online blackmail.

Against that backdrop, 163 recorded crimes across twenty forces is less a measurement of total harm than proof that AI-facilitated image abuse has crossed from niche concern into routine police workload — with the total almost certainly far higher than what forces have managed to tag.

The law is racing to catch up

The UK has spent 2026 assembling one of the most aggressive legal frameworks in the world for AI-generated image abuse:

  • February 2026: Creating explicit deepfake images became a criminal offence via the Data (Use and Access) Act — closing a gap where only sharing, not creation, was clearly illegal.
  • The Crime and Policing Act 2026 went further. Section 99 introduces a new offence of making or supplying “purported intimate image generators” — the AI nudify apps at the center of this week’s police data. The Act also criminalises AI chatbots that produce proscribed sexual content, and — in a world-first move first trailed in February 2025 — criminalises AI models that have been optimised to create child sexual abuse material, with penalties of up to five years for creating, possessing, or distributing such tools.
  • June 2026: The Home Office launched PoliceAI, a £75 million national centre whose Policing AI Threat Hub (PATH) is specifically tasked with coordinating the national response to AI-enabled crime, including deepfake intimate images.

Nandy’s ultimatum to Apple and Google

The most consequential development arrived four days before the Telegraph report. On September 8, Nandy told the Commons that the government will introduce primary legislation requiring major tech platforms to build device-level protections for children — making it impossible for under-18s to take, share, or view nude images on their phones and tablets.

The statement followed a three-month ultimatum issued in June, during which DCMS and Home Office officials ran what Nandy called an “unprecedented work programme” with Apple and Google. Both companies returned what she described as “significant commitments”: OS-level changes making it harder for children to share nude imagery, actual blocking rather than blurring on underage devices, and Apple’s rollout of operating-system-level age assurance tied to safety features in iMessage and FaceTime.

Her verdict was blunt: “These proposals are a step in the right direction. However, the truth is… they do not meet the scale of this crisis.” The government’s position — “we will give tech companies the chance to lead – we will not give them the chance to lag” — marks a shift from the voluntary-roadmap era to statutory duties, with app-level requirements for apps children use to follow.

Why this matters beyond Britain

Three lessons travel well beyond the UK.

First, measurement is arriving. Until now, AI’s harms have been tracked mostly by victim surveys and NGO telemetry. Police-recorded offence data — imperfect as it is — is the kind of number that parliaments, courts, and eventually insurers price in. Other jurisdictions should expect the same pattern: once forces start tagging, the count goes vertical.

Second, the enforcement chain is being built end-to-end. The UK is simultaneously criminalising the tools (nudify apps, CSAM-optimised models), the outputs (deepfake creation), the distribution (48-hour takedown duties), and now the platform layer (device-level blocking). Each link makes the previous ones enforceable.

Third, the tension between safety and privacy is about to be tested in hardware. Device-level blocking of imagery — on-device classification of photos and messages — is exactly the client-side scanning territory that provoked a civil-liberties revolt when Apple first floated it in 2021. The difference now is a legislature apparently willing to mandate it. How Apple and Google implement blocking that satisfies Westminster without reopening the surveillance debate may become the defining privacy fight of 2027.

The 163 cases behind this week’s headline are, in one sense, a rounding error against the IWF’s tens of thousands of actioned files. But as a signal of where this technology has landed — in the crime records of ordinary police forces, in the statute book, and now in the operating systems of every phone sold to a British teenager — the number is hard to ignore.